3.3

CVSS3.1

CVE-2025-27496 - Snowflake JDBC Driver client-side encryption key in DEBUG logs

Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption ma…

πŸ“… Published: March 13, 2025, 7:01 p.m. πŸ”„ Last Modified: March 13, 2025, 7:51 p.m.

8.5

CVSS4.0

CVE-2025-2229 - Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentials

A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations.

πŸ“… Published: March 13, 2025, 6:17 p.m. πŸ”„ Last Modified: March 13, 2025, 7:30 p.m.

8.5

CVSS4.0

CVE-2025-2230 - Philips Intellispace Cardiovascular (ISCV) Improper Authentication

A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authentication bypass.

πŸ“… Published: March 13, 2025, 6:14 p.m. πŸ”„ Last Modified: March 13, 2025, 7:34 p.m.

4.3

CVSS3.1

CVE-2024-30143 - A path traversal vulnerability in HCL AppScan Traffic Recorder

HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing it to resolve to a location beyond the restricted directory. Potential exploits can completely disrupt or takeover the application or the computer where the application is runnin…

πŸ“… Published: March 13, 2025, 5:34 p.m. πŸ”„ Last Modified: March 13, 2025, 6:15 p.m.

7.2

CVSS3.1

CVE-2025-24053 - Microsoft Dataverse Elevation of Privilege Vulnerability

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

πŸ“… Published: March 13, 2025, 5:25 p.m. πŸ”„ Last Modified: March 13, 2025, 6:26 p.m.

5.8

CVSS3.1

CVE-2025-29773 - Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Esc…

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and security. This vulnera…

πŸ“… Published: March 13, 2025, 5:07 p.m. πŸ”„ Last Modified: March 13, 2025, 7:15 p.m.

4.4

CVSS3.1

CVE-2025-29768 - Vim vulnerable to potential data loss with zip.vim and special crafted zip files

Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patc…

πŸ“… Published: March 13, 2025, 5:04 p.m. πŸ”„ Last Modified: March 13, 2025, 6:39 p.m.

8.7

CVSS4.0

CVE-2025-2081 -

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.

πŸ“… Published: March 13, 2025, 5 p.m. πŸ”„ Last Modified: March 13, 2025, 6:42 p.m.

9.3

CVSS4.0

CVE-2025-2080 -

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products.

πŸ“… Published: March 13, 2025, 4:57 p.m. πŸ”„ Last Modified: March 13, 2025, 6:46 p.m.

8.7

CVSS4.0

CVE-2025-2079 -

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions.

πŸ“… Published: March 13, 2025, 4:55 p.m. πŸ”„ Last Modified: March 13, 2025, 6:49 p.m.
Total resulsts: 285212
Page 1 of 28,522
Β» next page
Filters